{"id":"CVE-2017-9246","aliases":[],"url":"https://o3.security/vulnerability/CVE-2017-9246","summary":"New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated…","details":"New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES clause of an INSERT statement, after bypassing a SET SHOWPLAN_ALL ON protection mechanism.","published":"2017-06-13T18:29:00.187","modified":"2026-06-17T01:27:44.600","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"https://blog.seanmcelroy.com/2017/05/26/sql-injection-with-new-relic-patched/"},{"type":"EXPLOIT","url":"https://blog.seanmcelroy.com/2017/05/26/sql-injection-with-new-relic-patched/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T01:27:44.600"}}